Skip to content

fix(deps): pin oauthlib to 4.0.0 for oauthlib 3.3.1 CVE batch - #4552

Merged
Jan-Kazlouski-elastic merged 3 commits into
mainfrom
jan-kazlouski/16332-oauthlib-cve-fix
Oct 1, 2026
Merged

Jan-Kazlouski-elastic merged 3 commits into
mainfrom
jan-kazlouski/16332-oauthlib-cve-fix

Conversation

@Jan-Kazlouski-elastic

Copy link
Copy Markdown
Contributor

Part of

Summary

Pins oauthlib to 4.0.0 in app/connectors_service/pyproject.toml. The package is transitive (via requests-oauthlib / OAuth client flows); a direct pin is needed because no parent release forces 4.x yet.

Clears Snyk findings CVE-2026-49264 (XSS on revocation JSONP) and CVE-2026-49265 (PKCE timing side-channel on the authorization-server token endpoint).

Changes

  • app/connectors_service/pyproject.toml: oauthlib==4.0.0

Scanner A/B (2 CVE IDs)

Minimal venv A/B on oauthlib==3.3.1 vs oauthlib==4.0.0:

Tool Before (3.3.1) After (4.0.0)
pip-audit reported (CVE-2026-49265; advisory gap on -49264) clear
Trivy n/a n/a
Snyk reported (2 issues) clear

Test plan

  • make clean install autoformat lint test PYTHON=python3.11 — 2546 passed, 92.09% coverage
  • Scanner A/B — Snyk clear on 4.0.0

Changes Requiring Extra Attention

  • Security-related changes (dependency CVE remediation; oauthlib 4.x major pin)

Transitive dependency (via requests-oauthlib); direct pin clears timing
attack and XSS findings (CVE-2026-49265, CVE-2026-49264).

Part of elastic/search-team#16332
Part of elastic/search-team#16333
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic enabled auto-merge (squash) October 1, 2026 10:00
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic merged commit ccc2b80 into main Oct 1, 2026
2 checks passed
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic deleted the jan-kazlouski/16332-oauthlib-cve-fix branch October 1, 2026 10:44
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

💔 Failed to create backport PR(s)

Status Branch Result
✅ 9.4 #4557
✅ 9.5 #4558
❌ 8.19 Commit could not be cherrypicked due to conflicts

Successful backport PRs will be merged automatically after passing CI.

To backport manually run:
backport --pr 4552 --autoMerge --autoMergeMethod squash

Jan-Kazlouski-elastic added a commit that referenced this pull request Oct 1, 2026
…4552) (#4557)

Backports the following commits to 9.4:
 - fix(deps): pin oauthlib to 4.0.0 for oauthlib 3.3.1 CVE batch (#4552)

Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
Jan-Kazlouski-elastic added a commit that referenced this pull request Oct 1, 2026
…4552) (#4558)

Backports the following commits to 9.5:
 - fix(deps): pin oauthlib to 4.0.0 for oauthlib 3.3.1 CVE batch (#4552)

Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
Jan-Kazlouski-elastic added a commit that referenced this pull request Oct 2, 2026
…4552) (#4561)

## Part of

- elastic/search-team#16332
- elastic/search-team#16333

## Summary

Backport of #4552 for `8.19`: pin `oauthlib==4.0.0` in
`requirements/framework.txt` (8.19 uses requirements pins instead of
`pyproject.toml`).

## Test plan

- [ ] Buildkite green on `8.19`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants